CVE-2022-1902

Source
https://cve.org/CVERecord?id=CVE-2022-1902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1902
Published
2022-09-01T19:54:44Z
Modified
2026-07-15T01:49:12.754568990Z
Summary
[none]
Details

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

Database specific
{
    "cwe_ids": [
        "CWE-497"
    ],
    "cna_assigner": "redhat",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1902.json"
}
References

Affected packages

Git / github.com/stackrox/stackrox

Affected ranges

Type
GIT
Repo
https://github.com/stackrox/stackrox
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "Red Hat Advanced Cluster Security for Kubernetes 3"
        },
        {
            "last_affected": "Red Hat Advanced Cluster Security for Kubernetes 3"
        },
        {
            "introduced": "3.68"
        },
        {
            "last_affected": "3.68"
        },
        {
            "introduced": "3.69"
        },
        {
            "last_affected": "3.69"
        },
        {
            "introduced": "3.70"
        },
        {
            "last_affected": "3.70"
        }
    ],
    "cpe": [
        "cpe:2.3:a:redhat:advanced_cluster_security:3.68:*:*:*:*:kubernates:*:*",
        "cpe:2.3:a:redhat:advanced_cluster_security:3.69:*:*:*:*:kubernates:*:*",
        "cpe:2.3:a:redhat:advanced_cluster_security:3.70:*:*:*:*:kubernates:*:*"
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

3.*
3.68
3.69
3.70
3.x
4.*
4.3
4.3.x
Other
Red Hat Advanced Cluster Security for Kubernetes 3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1902.json"